Junglewise Threat Intelligence

CVE-2021-38163: SAP NetWeaver Unrestricted File Upload Vulnerability

CVE-2021-38163 · Severity: critical · CVSS 9.9 · Exploited in the wild · Published 2022-06-09

Technologies: SAP NetWeaver. Vendors: SAP SE, SAP.

Executive brief

SAP NetWeaver (Visual Composer 7.0 RT) allows an authenticated non-administrative user to upload malicious files over a network. Successful exploitation enables the execution of operating system commands with the privileges of the Java Server process, potentially leading to full system compromise or denial of service.

Affected products

  • SAP SE NetWeaver (Visual Composer 7.0 RT) 7.30, 7.31, 7.40, 7.50

Timeline

  • 2021-09-14: disclosed: NVD Published Date
  • 2022-06-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats